Live data from Hacker News

Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

wired.com

31–40 of 121 posts

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#31
post #2

I'm looking at Juniper's news page [1] and its Twitter feed [2]...it doesn't give me a lot of confidence that this security breach or even its (apparently inadequate) patch doesn't even a news item or a Tweet. [1] http://newsroom.juniper.net/ [2] https://twitter.com/JuniperNetworks/with_replies

At least their notice went out on a Thursday, instead of waiting until late Friday evening or, worse, next Friday evening (by which time a large percentage of the engineers managing these boxes will be on vacation).

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#33

I'm confused. Are these accidental vulnerabilities or deliberate backdoors? If deliberate, why is there speculation about who might have installed this "secret code"? Do they have version control? Is there a specific human attached to the relevant commits? Serious question.

They might know the person, but not necessarily their affiliation. They might want to investigate before they divulge. If it's a US person, it takes time or would never be divulged.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#34
post #6

It's sad but events like this one make me turn away from Internet. I started using Signal because I don't want people seeing the messages I post. But in the end it's only trust that makes me think Signal is safe to use. A lot of people also trusted Juniper. But that trust is gone. And not only for Juniper. What about other brands? We don't know.

Signal is open source. But you have to trust the OS it runs on...

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#35
post #9

Wow that nation state is stupid. They embedded the backdoor password right into it. Clearly they should have embedded the hash of the password instead. Then it would be unbreakable and no other party would be able to use the backdoor. Hashing passwords is extremely basic security practice.

When you're trying to do something secretly, you run into a new tradeoff: doing it the right way vs. doing it in such a way that it doesn't draw attention to itself. It might have been the case that hashing it would have been too flashy.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#36
post #34
post #6

It's sad but events like this one make me turn away from Internet. I started using Signal because I don't want people seeing the messages I post. But in the end it's only trust that makes me think Signal is safe to use. A lot of people also trusted Juniper. But that trust is gone. And not only for Juniper. What about other brands? We don't know.

Signal is open source. But you have to trust the OS it runs on...

And the hardware the OS runs on... Intel and others are now embedding "management" features at a very low level.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#37
post #34
post #6

It's sad but events like this one make me turn away from Internet. I started using Signal because I don't want people seeing the messages I post. But in the end it's only trust that makes me think Signal is safe to use. A lot of people also trusted Juniper. But that trust is gone. And not only for Juniper. What about other brands? We don't know.

Signal is open source. But you have to trust the OS it runs on...

And even if you trust the OS, you have no idea what is going on on the phone's baseband processor: https://en.m.wikipedia.org/wiki/Baseband_processor

One has to assume that all are back-doored. Mobile phones are inherently not trustable.

Same goes for all major firewall vendors. If you going to hack one of them as a nation state, then you're going to do all of them.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#38
I'll bet you ten dollars there are more backdoors, better hidden than the ones they found. Say, with Underhanded C style coding. An additional ten bucks says that Cisco and the top handful of consumer appliances also contain such backdoors.

I hope the folks at Juniper are checking their toolchains, build machines and repositories for signs of similar attack. Of course, enough time has elapsed that they may need to establish a cleanroom for their code. Hoo boy.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#39

I like CNN's take on the story: http://edition.cnn.com/2015/12/18/politics/juniper-networks-... Obviously it must be either Russia or China - NSA couldn't possibly be responsible ;)

It can't be NSA agents who caught intercepting network gear from Cisco Systems as it was being shipped to a customer (as revealed by snowden) it is highly unlikely they infected juniper networks as well.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#40
post #32

Don't gouvernements can check the source code? like for Windows?

It's an interesting thought. If they checked and spotted this would they report it to defend against the attacker that injected it, or would they just pocket the master password and use it themselves?
Post reply on HN